Event names are checked now, per manifest and across the catalogue
Issue 127 stood because nothing compared the two halves. Every manifest was well-formed on its own and every derivation correct on its own, and no cross-module subscription in the mesh matched anything — a subscription that matches nothing is not an error, it is silence. Two checks, because the mistake is possible at two scales. Per manifest: an event is a local name, and `module.` is refused with the name to write instead. A module emitting under what reads as another module's name is refused too, pointing at the seat, where a name outlives whoever holds it. Across the catalogue: where a consumed event's emitter is present, it must emit that event. It cannot demand a live emitter for everything — a module lives in its own repository and may be installed long before the one whose events it wants — so the rule is narrower and still catches this. It found two real dangling subscriptions the moment it ran. Wildcards were undecided and two manifests needed them: `*` is one name and `**` is the rest, spelled the mesh's way and derived to `>` here and `#` on the old bus. A manifest naming either would stop being true when the wire changed, which is the whole reason names are local. And the field documentation taught the old form, examples included — which is why the drift was uniform across 37 manifests rather than scattered. Nobody was guessing; everybody followed the comment.
This commit is contained in:
+51
-5
@@ -241,12 +241,11 @@ func PermissionsFor(p Principal) (Permissions, error) {
|
||||
// 2. What it consumes, by the emitter's own subject — an event is addressed to its
|
||||
// emitter, because the emitter's identity is the meaning (ADR 0118).
|
||||
for _, c := range p.Consumes {
|
||||
emitter, event, ok := strings.Cut(c, ".")
|
||||
if !ok {
|
||||
return Permissions{}, fmt.Errorf(
|
||||
"%q does not name an emitter and an event: a consumed event is <module>.<event>", c)
|
||||
subject, err := consumedSubject(c)
|
||||
if err != nil {
|
||||
return Permissions{}, err
|
||||
}
|
||||
sub = append(sub, "mesh.mod."+emitter+".event."+event)
|
||||
sub = append(sub, subject)
|
||||
}
|
||||
|
||||
// 3. Seats it holds: full participation.
|
||||
@@ -331,6 +330,53 @@ func seatSubject(s Seat, kind, verb string) string {
|
||||
//
|
||||
// They are derived here, beside the permission that must match them, because two places deriving
|
||||
// the same name is how a module ends up unable to ack its own deliveries.
|
||||
// consumedSubject is where a consumed event lands, from the local pattern a module declared.
|
||||
//
|
||||
// **The mesh's wildcards become this transport's** (design 29 §1): `*` is one name on both, and `**`
|
||||
// — the rest — is `>` here. A module writes neither transport's spelling, so a manifest stays correct
|
||||
// when the wire changes, which is the whole reason names are local.
|
||||
//
|
||||
// `**` on its own is every event from every module: the emitter is any, the event is anything. An
|
||||
// audit logger wants exactly that and says so in one token.
|
||||
func consumedSubject(pattern string) (string, error) {
|
||||
if pattern == catalogueTheRest {
|
||||
return "mesh.mod.*.event.>", nil
|
||||
}
|
||||
emitter, event, named := strings.Cut(pattern, ".")
|
||||
if !named || emitter == "" || event == "" {
|
||||
return "", fmt.Errorf(
|
||||
"%q does not name an emitter and an event: a consumed event is <emitter>.<event>, or "+
|
||||
"%q for every event", pattern, catalogueTheRest)
|
||||
}
|
||||
if emitter == catalogueTheRest {
|
||||
return "", fmt.Errorf("%q stands for the rest of a name, so it cannot name the emitter", catalogueTheRest)
|
||||
}
|
||||
// Each name is checked before it becomes a subject: a name carrying a dot would add a token and
|
||||
// silently widen the permission, which is the whole reason safeSubject exists.
|
||||
var out []string
|
||||
for _, part := range strings.Split(event, ".") {
|
||||
switch part {
|
||||
case catalogueTheRest:
|
||||
out = append(out, ">")
|
||||
case "*":
|
||||
out = append(out, "*")
|
||||
default:
|
||||
if !safeSubject.MatchString(part) {
|
||||
return "", fmt.Errorf("%q cannot be part of a subject: it would widen the permission", part)
|
||||
}
|
||||
out = append(out, part)
|
||||
}
|
||||
}
|
||||
if emitter != "*" && !safeSubject.MatchString(emitter) {
|
||||
return "", fmt.Errorf("%q cannot name an emitter: it would widen the permission", emitter)
|
||||
}
|
||||
return "mesh.mod." + emitter + ".event." + strings.Join(out, "."), nil
|
||||
}
|
||||
|
||||
// catalogueTheRest is the mesh's wildcard for "the rest of a name", duplicated from the catalogue
|
||||
// package for the one direction of dependency the build queue's name is duplicated for.
|
||||
const catalogueTheRest = "**"
|
||||
|
||||
func consumerStream(p Principal) string {
|
||||
switch p.Kind {
|
||||
case KindModule:
|
||||
|
||||
Reference in New Issue
Block a user